Privacy
Glossary

Data protection impact assessment

A data protection impact assessment examines before processing starts whether a planned operation is likely to create a high risk to people’s rights and freedoms and how that risk can be reduced.

In brief

A data protection impact assessment (DPIA) under Article 35 GDPR is a structured assessment carried out before processing begins. The controller describes the planned processing and its purposes, assesses necessity and proportionality, evaluates possible risks to data subjects and identifies safeguards. The assessment should start early, especially where new technologies or processing operations are likely to result in a high risk.

A DPIA is particularly required where people are systematically and extensively evaluated, where special categories of personal data or data relating to criminal convictions and offences are processed on a large scale, or where a publicly accessible area is systematically monitored on a large scale. The supervisory authority may publish a list of further processing operations requiring an assessment. If a high residual risk remains despite the safeguards, the controller must consult the supervisory authority before starting the processing.

In practice, the DPIA should be connected to the specific processing operation, data flows, access permissions, retention periods and technical and organisational measures. Where a data protection officer has been appointed, the controller must seek the officer’s advice. The privacy compliance and governance topic helps allocate responsibilities; the page on marketing, cookies and tracking provides context for tracking and profiling.

General orientation, not individual advice.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich